Remote Code Execution Vulnerability in PHP by The PHP Group
CVE-2004-1019
Currently unrated
What is CVE-2004-1019?
The deserialization process in versions of PHP prior to 4.3.10 and 5.x up to 5.0.2 contains a vulnerability that allows remote attackers to send specially crafted data to the unserialize function. This can lead to a denial of service, execution of arbitrary code, and potential information disclosure. The flaw can trigger conditions such as double-free errors and underflow in negative reference index arrays, posing significant security risks to applications utilizing these PHP versions.
References
EPSS Score
7% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved